<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Mapping fields to XSOAR IOCs in Cortex XSOAR Discussions</title>
    <link>https://live.paloaltonetworks.com/t5/cortex-xsoar-discussions/mapping-fields-to-xsoar-iocs/m-p/552199#M2452</link>
    <description>&lt;P&gt;You can also perform mapping to Indicator fields for enrichment data on the Indicator Type itself.&amp;nbsp;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;BR /&gt;Navigating to Settings -&amp;gt; Object Setup -&amp;gt; Indicators -&amp;gt; Types, and edit the Type you want.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;BR /&gt;Select Custom Fields, and load the indicator, and you can map the values in the indicators context to fields, which will be set upon enrichment (or re-enrichment for the current indicator after you're done)&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Screenshot 2023-08-02 at 7.55.15 AM.png" style="width: 999px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/52477i70AD157444957C47/image-size/large?v=v2&amp;amp;px=999" role="button" title="Screenshot 2023-08-02 at 7.55.15 AM.png" alt="Screenshot 2023-08-02 at 7.55.15 AM.png" /&gt;&lt;/span&gt;&lt;/P&gt;</description>
    <pubDate>Wed, 02 Aug 2023 13:57:32 GMT</pubDate>
    <dc:creator>MBeauchamp2</dc:creator>
    <dc:date>2023-08-02T13:57:32Z</dc:date>
    <item>
      <title>Mapping fields to XSOAR IOCs</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xsoar-discussions/mapping-fields-to-xsoar-iocs/m-p/552082#M2439</link>
      <description>&lt;P&gt;I'd appreicate guidance on how to update IOC fields with information extracted from an excuted playbook task.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;My use case centers around updating File Hash IOCs to include file signature metadata information to enable easier cleaning up of IOCs associated with known vendors such as Microsoft.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Any assistance is appreciated.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 01 Aug 2023 14:53:53 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xsoar-discussions/mapping-fields-to-xsoar-iocs/m-p/552082#M2439</guid>
      <dc:creator>jemeche</dc:creator>
      <dc:date>2023-08-01T14:53:53Z</dc:date>
    </item>
    <item>
      <title>Re: Mapping fields to XSOAR IOCs</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xsoar-discussions/mapping-fields-to-xsoar-iocs/m-p/552171#M2451</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/297912"&gt;@jemeche&lt;/a&gt;&amp;nbsp;,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;You can make use of tags for that purpose. First, use appendIndicatorField automation to add a tag and then you can use that tag to filter tagged IOCs. I hope this answers your question.&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="gyldz_0-1690968400289.png" style="width: 400px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/52471i8E2948D1A265B091/image-size/medium/is-moderation-mode/true?v=v2&amp;amp;px=400" role="button" title="gyldz_0-1690968400289.png" alt="gyldz_0-1690968400289.png" /&gt;&lt;/span&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="gyldz_1-1690968457550.png" style="width: 400px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/52472i0C0633C284A0C136/image-size/medium/is-moderation-mode/true?v=v2&amp;amp;px=400" role="button" title="gyldz_1-1690968457550.png" alt="gyldz_1-1690968457550.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 02 Aug 2023 09:28:05 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xsoar-discussions/mapping-fields-to-xsoar-iocs/m-p/552171#M2451</guid>
      <dc:creator>gyldz</dc:creator>
      <dc:date>2023-08-02T09:28:05Z</dc:date>
    </item>
    <item>
      <title>Re: Mapping fields to XSOAR IOCs</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xsoar-discussions/mapping-fields-to-xsoar-iocs/m-p/552199#M2452</link>
      <description>&lt;P&gt;You can also perform mapping to Indicator fields for enrichment data on the Indicator Type itself.&amp;nbsp;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;BR /&gt;Navigating to Settings -&amp;gt; Object Setup -&amp;gt; Indicators -&amp;gt; Types, and edit the Type you want.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;BR /&gt;Select Custom Fields, and load the indicator, and you can map the values in the indicators context to fields, which will be set upon enrichment (or re-enrichment for the current indicator after you're done)&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Screenshot 2023-08-02 at 7.55.15 AM.png" style="width: 999px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/52477i70AD157444957C47/image-size/large?v=v2&amp;amp;px=999" role="button" title="Screenshot 2023-08-02 at 7.55.15 AM.png" alt="Screenshot 2023-08-02 at 7.55.15 AM.png" /&gt;&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 02 Aug 2023 13:57:32 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xsoar-discussions/mapping-fields-to-xsoar-iocs/m-p/552199#M2452</guid>
      <dc:creator>MBeauchamp2</dc:creator>
      <dc:date>2023-08-02T13:57:32Z</dc:date>
    </item>
    <item>
      <title>Re: Mapping fields to XSOAR IOCs</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xsoar-discussions/mapping-fields-to-xsoar-iocs/m-p/552314#M2458</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;
&lt;P&gt;To update IOCs with file signature metadata, extract relevant information from the executed playbook task. Fetch existing IOCs from the database, match file hashes with extracted data, and update corresponding fields. Save the updated IOCs back to storage. Automate the process for regular updates. Prioritize security and access controls while handling sensitive information. Validate data accuracy regularly and test automation in a controlled environment before deployment. Use appropriate tools and scripting capabilities for implementation. Ensure compliance with security protocols and consider integrating with security automation platforms for efficiency.&lt;/P&gt;
&lt;P&gt;Best regard,&lt;/P&gt;</description>
      <pubDate>Thu, 03 Aug 2023 06:07:16 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xsoar-discussions/mapping-fields-to-xsoar-iocs/m-p/552314#M2458</guid>
      <dc:creator>Azxkolki</dc:creator>
      <dc:date>2023-08-03T06:07:16Z</dc:date>
    </item>
  </channel>
</rss>

